CVE-2025-0285

Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is caused by a failure to properly validate the length of user supplied data, which can allow an attacker to perform privilege escalation exploits.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
certccCNA
---
---
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
VendorProductVersion
paragon-softwareparagon_backup_\&_recovery
15 ≤
𝑥
≤ 17.39
paragon-softwareparagon_disk_wiper
15 ≤
𝑥
≤ 16
paragon-softwareparagon_drive_copy
15 ≤
𝑥
≤ 16
paragon-softwareparagon_hard_disk_manager
15 ≤
𝑥
≤ 17.39
paragon-softwareparagon_migrate_os_to_ssd
4 ≤
𝑥
≤ 5
paragon-softwareparagon_partition_manager
15 ≤
𝑥
≤ 17.39
𝑥
= Vulnerable software versions